Ransomware

Conduent Business Services SafePay Ransomware Attack

πŸ“… 2024-10-21 🦠 SafePay ransomware
Primary Source β†—

Incident Details

Conduent, a company providing payment processing and document services to major health insurers and state government programs, was breached by the SafePay ransomware group. Attackers had access from October 21, 2024 to January 13, 2025, exfiltrating over 8 terabytes of data. At least 25 million Americans were affected; ~15.5 million in Texas alone. Stolen data included names, SSNs, medical and health insurance information. SafePay threatened to publish data if ransom was not paid; Conduent is no longer listed on the leak site (ransom likely paid or data sold). Texas AG investigation opened. At least 10 federal class action lawsuits filed by February 2026. Considered by some sources as potentially the largest breach in US history by record count.

Technical Details

Initial Attack Vector
Unknown initial access; attackers had persistent access from October 21, 2024 to January 13, 2025
Malware Family
SafePay ransomware

Timeline

  1. 2024-10-21 Breach occurred
  2. 2025-02-01 Publicly disclosed
  3. 2025-06-01 Customers notified